EU AI Act: The High-Risk Deadline Was Delayed. The Disclosure Rules Were Not.

Posted on
EU AI Act compliance checklist for marketing teams — legal regulation concept

There has been a lot of confusion about what the EU AI Act requires from marketers starting today. Most of the coverage focused on the high-risk AI provisions, conformity assessments, technical documentation, registration in the EU database, and then quietly stopped mentioning that those requirements were delayed.

They were. In May 2026, the EU’s Digital Omnibus agreement pushed the main high-risk AI obligations back: standalone high-risk systems to December 2027, and AI built into regulated products to August 2028. If your team spent the last few months bracing for a compliance cliff on August 2, the deadline moved. The requirements that everyone was nervous about are now more than a year away.

What did not get delayed is Article 50. And that is the part that hits marketing operations directly.

What Article 50 actually requires

Article 50 is the EU AI Act’s transparency and disclosure rule. Starting today, it requires clear disclosure when users are interacting with an AI chatbot that could be mistaken for a human, when content has been artificially generated in a way that could mislead (synthetic video, audio, or images that simulate real people or real events), and when a synthetic voice has been used without disclosure.

The rule is about what users could reasonably mistake for something real. A blog post drafted with AI help is not the target. A chatbot that presents itself as a human customer service agent is.

Fines sit at up to 15 million euros or 3% of global annual turnover, enforced by national market surveillance authorities. How hard enforcement bites will vary by country. Some national bodies have more resources and appetite than others, and this is a regulation with no meaningful enforcement track record yet. But the rule is active from today.

Where things get genuinely unclear

A few grey areas worth understanding before you assume you are either fully covered or definitely exposed:

AI-assisted copy vs. AI-generated content. The current guidance distinguishes between content “perceptibly generated” by AI and content where a human used AI as one tool among several. A newsletter where you used AI to research, draft, and refine, then edited and published yourself, is not currently in Article 50’s scope. A newsletter generated entirely by an AI tool and sent without meaningful human input is closer to the line. Where exactly that line sits will be tested through enforcement over the next 12 to 18 months.

AI avatars and synthetic presenters. If you have been using AI video tools to create talking-head presenters for your brand, even for training content or product explainers, and those videos reach an EU audience, this is worth reviewing. Disclosure does not mean stopping. It means telling viewers what they are watching.

Named chatbot characters. If a chatbot identifies as a brand character or named assistant without making clear it is AI, that is precisely what Article 50 targets. Most enterprise chatbot platforms already include disclosure elements. If you built something custom, check.

A practical checklist for marketing teams

This is not legal advice, anything binding should go through actual legal counsel. But here is a working check your team can run today:

  • Website chatbots: Is there a visible “You are chatting with an AI” message? If not, add one.
  • AI-generated video with synthetic presenters: Any content reaching EU users needs disclosure. A label in the description is a start; clearer is better.
  • Synthetic voiceovers: If the voice was AI-generated and could be mistaken for a real named person’s voice, disclose it.
  • Email from an AI persona: An AI persona presented as a named human without disclosure is the problem. A named AI assistant that is clearly an assistant is fine.
  • Social media: Meta’s automatic AI labelling tool is live across Facebook and Instagram. Check it is switched on for your content where relevant.

One thing many teams miss: if you are based outside the EU but your content or chatbots reach EU users, the Act applies to you. The regulation is based on where the user is located, not where the company is registered.

What compliance looks like in practice

The marketers handling this well are not the ones with the most elaborate disclosure frameworks. They are the ones whose content decisions do not depend on users not realising AI was involved. Disclosure is much easier when you have been building with honesty as a default.

Most AI content problems are not compliance failures. They are quality and transparency failures that happen to involve AI. Article 50 created a legal minimum where there was previously only an ethical expectation.

For platform-level rules on AI content, what YouTube, Google, and Meta actually require, see our AI Content Policy for Marketers guide from earlier this week. The EU Act is one layer; platform rules are another, and they do not always align.

The kind of AI marketing workflow that survives both platform policies and regulatory scrutiny is one built around human judgment, not volume. That is the approach mark8ng.ai is designed around.

Editor’s note: EU AI Act enforcement guidance is still being developed by national authorities. The Article 50 requirements are clear in principle, but how they apply to specific marketing contexts will be clarified through early enforcement decisions over the coming months. Check the EU AI Office and your national data protection authority for updates before making compliance decisions based on this article.

Update, 2 August 2026: enforcement is now live

The European Commission confirmed that from 2 August the AI Office, working with national authorities, has begun enforcing the AI Act, and the transparency rules covered above now apply. The AI Office’s powers over general-purpose AI models include requesting technical documentation, commissioning independent evaluations, requiring corrective measures, and issuing fines of up to 3% of global annual turnover.

For marketing teams, nothing in the practical checklist above changes. The obligations were always the transparency ones: telling people when they are talking to an AI rather than a person, and labelling synthetic or manipulated content. What changed on 2 August is that there is now an authority positioned to act on them. The realistic near-term risk for a small team is still not a regulator’s letter, it is a client or a platform asking for an AI-use declaration you cannot produce.

Update, 3 August 2026: the transparency rules are now enforceable

The deadline arrived. As of 2 August the Commission has begun enforcing the transparency requirements and published accompanying guidance. Obligations cover four areas: direct interaction with people, AI-generated content, emotion recognition and biometric categorisation, and deep fakes or AI-generated text on matters of public interest. Fines reach 15 million euro or 3% of global annual turnover. Work has also started on a code of practice for marking and labelling AI-generated content, so the detail of how you label is still being written.

The advice in this post stands unchanged. The checklist above was built around these obligations rather than the delayed high-risk ones, so nothing in it needs revising.

One detail has surfaced since publication that is worth acting on today. Content generated before 2 August does not need retroactive labelling if it was also published before that date. If it was generated in July but publishes on or after 2 August, the labelling obligation applies. Anyone sitting on a scheduled queue of AI-assisted images, video or synthetic voice built during the summer should check the publish dates rather than the creation dates.

Update, 4 August 2026: the Commission’s enforcement powers are now active

The transparency obligations described above took effect on 2 August. On the same date the European Commission, acting through its AI Office, gained the power to enforce them against providers of general purpose AI models. Those powers include requesting information and documentation, obtaining access to models for evaluation, requiring corrective or risk mitigation measures, and issuing fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. They apply to any company offering a general purpose model in the EU regardless of where it is based, and non-EU providers must appoint an EU-based authorised representative.

The AI Office has signalled that “technical compliance dialogues” are its preferred first step rather than immediate formal action, so the realistic near-term effect is pressure on the model providers, not on the marketing teams using them. That said, the direction of travel is worth watching: obligations that model providers absorb tend to reappear as terms of service changes and new attestation requirements further down the chain.

The advice in the original post is unchanged. Article 50 still applies to you directly, the labelling questions are still the ones to answer, and the compliance checklist above still holds. What has changed is the cost of the vendors above you getting it wrong, which is now measured in percentages of global turnover rather than in reputational risk.

Update, 6 August 2026: enforcement started, and the rules moved underneath it

Two things happened after this post went up. The European Commission AI Office and national authorities began enforcing the general-purpose model obligations on 2 August, so the machinery that asks questions now exists rather than being scheduled. Separately, the Digital Omnibus has changed parts of the original text, which means anyone who built a compliance checklist from the 2024 wording is working from a document that no longer matches.

The advice in this post still stands. Disclosure was always the part that applied to ordinary marketing teams, and it still is. What has changed is the cost of guessing. Before, an incorrect reading was a risk on paper. Now there is an office with a mandate to ask, and the answer you give will come from whatever process you actually have rather than whatever you intended to build.

If you have not written down who checks AI-generated assets before they publish, that is the gap worth closing this month. Compare your notes against the current consolidated text rather than the version you read last year.